UAC-0226, also tracked as SHADOW-EARTH-066, is a Russia-aligned cyber-espionage threat cluster focused on Ukrainian targets, particularly military, government, law-enforcement, and related public-sector organizations. The group is associated with deployment of the GIFTEDCROOK information-stealer family and later evolved variants that expanded from relatively simple credential theft into more mature in-memory espionage tooling. The actor has been observed using spear-phishing with Ukraine-themed lures to deliver malicious archives and exploit WinRAR vulnerability CVE-2025-8088 for initial access and persistence. In observed campaigns, the exploit chain silently places startup-executed artifacts and launches an obfuscated PowerShell loader that decrypts and executes payloads in memory. The malware demonstrates deliberate defense evasion, including dynamic API resolution, direct system-call techniques associated with Hell’s Gate-style tradecraft, manual payload mapping, and reduced on-disk artifacts. Its primary mission appears to be intelligence collection. GIFTEDCROOK-family payloads attributed to this actor steal browser credentials, cookies, session material, and local documents from major browsers including Chrome, Edge, Opera, and Firefox. The tooling has also been reported to recover browser decryption material, including bypassing Chrome App-Bound Encryption in newer variants, and to search victim systems for documents and other files of operational interest before compressing, encrypting, and exfiltrating the data over HTTPS. The cluster shows a notable progression in capability. Earlier activity linked to GIFTEDCROOK relied on simpler delivery and exfiltration mechanisms, while later operations used encrypted command-and-control, in-memory DLL execution, browser-process injection to access protected secrets, self-cleanup, and anti-analysis measures. Reporting has described result.dll as a direct evolution of GIFTEDCROOK based on malware lineage and technical overlap. Known aliases include SHADOW-EARTH-066 and UAC-0226. The actor is distinct from Earth Dahu, also known as Gamaredon or UAC-0010, although both have exploited the same WinRAR vulnerability against Ukrainian organizations. UAC-0226 is best characterized as a Russia-aligned espionage operator specializing in credential theft, document theft, and stealthy post-exploitation against Ukrainian state and military entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a targeted cyber-espionage campaign using spear-phishing and a WinRAR path traversal flaw to deliver the GIFTEDCROOK stealer against Ukrainian military and government entities.
Russia-aligned campaign exploiting WinRAR CVE-2025-8088 against Ukrainian organizations for credential and document theft, evolving from simpler macro-based tradecraft to exploit chains and encrypted C2.
Espionage-focused intrusions against Ukrainian organizations using malicious RAR archives that exploit CVE-2025-8088 to deploy an updated GIFTEDCROOK stealer for credential, cookie, and file theft.
Espionage-focused activity cluster exploiting CVE-2025-8088 against Ukrainian organizations, evolving from macro-based theft using GIFTEDCROOK and Telegram exfiltration to more advanced WinRAR exploit chains, in-memory DLL loading, credential theft, file collection, and encrypted HTTPS exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.